This update for python-django-ckeditor fixes the following issues:
- Update to 6.7.2
* Deprecated the package.
* Added a new ckeditor/fixups.js script which disables the version check
again (if something slips through by accident) and which disables the
behavior where CKEditor 4 would automatically attach itself to
unrelated HTML elements with a contenteditable attribute (see
CKEDITOR.disableAutoInline in the CKEditor 4 docs).
- CVE-2024-24815: Fixed bypass of Advanced Content Filtering mechanism
(boo#1219720)
- update to 6.7.1:
* Add Python 3.12, Django 5.0
* Silence the CKEditor version check/nag but include a system check
warning
- update to 6.7.0:
* Dark mode fixes.
* Added support for Pillow 10.
- update to 6.6.1:
* Required a newer version of django-js-asset which actually works with
Django 4.1.
* CKEditor 4.21.0
* Fixed the CKEditor styles when used with the dark...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP5:
zypper in -t patch openSUSE-2025-8=1
- openSUSE Backports SLE-15-SP5 (noarch):
python311-django-ckeditor-6.7.2-bp155.3.3.1
https://www.suse.com/security/cve/CVE-2024-24815.html
https://bugzilla.suse.com/1219720
Get the latest Linux and open source security news straight to your inbox.